Computer Hope

Computer Hope Forum Welcome, Guest. Please login or register.
November 22, 2009, 01:03:30 PM
Home Help Staff Chat Login Register
News: Have your own custom built computer? Come join the self-built computer club.

Computer Hope Forums  >>  Software  >>  Computer viruses and spyware (Moderator: Computer Hope Admin)  >>  Topic: Re: Cannot remove this virus which started with Win32:JunkPoly [Cryp] 0 Members and 1 Guest are viewing this topic. « previous next »
Pages: 1 [2]  All - (Bottom) Print
Author Topic: Re: Cannot remove this virus which started with Win32:JunkPoly [Cryp]  (Read 3654 times)
evilfantasy
Malware Removal Specialist
Genius
*
Posts: 10090

Thanked: 314
OS: Unknown
Experience: Beginner



Calm like a bomb


WWW
« Reply #15 on: April 23, 2009, 11:19:07 AM »

This is why my first and only suggestion when I see virut is to reformat and reinstall. Until then you can never be sure if the computer is clean or not.

Stay away from warez. It only takes one click and it's all over...
Logged

astrosoup
Newbie
*
Posts: 1

Thanked: 1
OS: Windows Vista
Experience: Experienced


« Reply #16 on: April 23, 2009, 12:54:04 PM »

Virut adds one or more iFrame tags to any html file it finds to redirect users to an exploit site.

Edit any html file on the infected computer and you'll see something like this at the bottom:

Code:
<- iframe src="http://ZieF,pl/rc/" width=1 height=1 style="border:'<- / iframe>',0Dh,0Ah

Virut makes similar changes to other file types such as .PHP, .ASP and .HTM, and is very hard for scanners to detect. So FYI don't bring web documents over in the backup when this infection finally brings you to your knees.

The most damning property of Virut is that it is polymorphic- it changes slightly with each replication, allowing some of the files infected to elude scanners. So if you scan your system with a boot cd repeatedly and follow up with a repair install, you may get virut to low for a while, but there is likely a file somewhere on your machine that will inevitably be activated before long, starting the entire infection over again.

Trying to remove Virut is an effort in futility, which is why evilfantasy and virtually every other malware expert who has experience with this infection will tell you that your only option is to reformat and reinstall, and to be careful what you transfer from your previous installation.

But feel free to keep trying. You'll just end up learning the hard way like I did.  Grin
Logged
evilfantasy
Malware Removal Specialist
Genius
*
Posts: 10090

Thanked: 314
OS: Unknown
Experience: Beginner



Calm like a bomb


WWW
« Reply #17 on: April 23, 2009, 12:58:19 PM »

Great post astrosoup and welcome to CH.
Logged

Helpmeh
Expert
*
Posts: 2186

Thanked: 61
OS: Windows XP
Experience: Familiar



Can you see this as it truly is? >< Tell me.


« Reply #18 on: April 23, 2009, 06:01:24 PM »

Great post astrosoup and welcome to CH.
That site is known to give you Bloodhound.Exploit.196, is blocked by google and is rated extremely poorly on WOT...(link from googling http://ZieF.pl/rc/ that link doesn't go to the site for safety reasons)

For more information go to http://www.google.com/safebrowsing/diagnostic?site=http://zief.pl/rc/&hl=en

Visiting a site that has been injected with the iframe code while currently using the NoScript addon for firefox will not affect you as NoScript blocks iframes. But going to the actual website will infect you...I wonder if viewing the page source will get me infected...
Logged


>< If you have this, you can see it. ><
I love 
evilfantasy
Malware Removal Specialist
Genius
*
Posts: 10090

Thanked: 314
OS: Unknown
Experience: Beginner



Calm like a bomb


WWW
« Reply #19 on: April 23, 2009, 07:12:43 PM »

It's definitely a nasty site. Does a LOT of damage. http://www.threatexpert.com/report.aspx?md5=71eb4db6da3338655c1ec3cb48489d03
Logged

sxkorn
Topic Starter
Greenhorn
*
Posts: 8

Thanked: 0
OS: Windows Vista
Experience: Familiar




« Reply #20 on: April 24, 2009, 05:42:03 AM »

So if you scan your system with a boot cd repeatedly and follow up with a repair install, you may get virut to low for a while, but there is likely a file somewhere on your machine that will inevitably be activated before long, starting the entire infection over again.
Like I said, I did not perform a reinstall and deleted all the files from the previous system. The current system is a fresh install and I previously formated the current system partition. All I did I kept other files, which were not infected according to kaspersky tool.

Virut adds one or more iFrame tags to any html file it finds to redirect users to an exploit site.

Edit any html file on the infected computer and you'll see something like this at the bottom:

Code:
<- iframe src="http://ZieF,pl/rc/" width=1 height=1 style="border:'<- / iframe>',0Dh,0Ah

Virut makes similar changes to other file types such as .PHP, .ASP and .HTM, and is very hard for scanners to detect. So FYI don't bring web documents over in the backup when this infection finally brings you to your knees.
The iFrame problem, mentioned in an earlier post, happened on my wife's computer, while browsing. It was not a web file on the computer and avast blocked access to that page. That computer was not infected and I scanned it just in case [no sign of virut found, like I said].

But feel free to keep trying. You'll just end up learning the hard way like I did
If I get it again, from the files I have on my computer, I will let you know. But I'm not ready to throw all I have as long as I don't have a reason just yet. I would delete infected files, but not those found not to be infected. Maybe I'm wrong, maybe not. I'll see and let u know.
Logged
Pages: 1 [2]  All - (Top) Print 
Computer Hope Forums  >>  Software  >>  Computer viruses and spyware (Moderator: Computer Hope Admin)  >>  Topic: Re: Cannot remove this virus which started with Win32:JunkPoly [Cryp] « previous next »
Jump to:  


Login with username, password and session length

Old Forum Search | Forum Rules
Copyright 1998-2008 by Computer Hope (tm). All rights reserved
Powered by SMF 1.1.8 | SMF © 2006-2008, Simple Machines LLC
Page created in 0.09 seconds with 18 queries.